9.8

CVE-2021-43215

iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 10 Version- HwPlatformx64
MicrosoftWindows 10 Version- HwPlatformx86
MicrosoftWindows 10 Version20h2 HwPlatformarm64
MicrosoftWindows 10 Version20h2 HwPlatformx64
MicrosoftWindows 10 Version20h2 HwPlatformx86
MicrosoftWindows 10 Version21h1 HwPlatformarm64
MicrosoftWindows 10 Version21h1 HwPlatformx64
MicrosoftWindows 10 Version21h1 HwPlatformx86
MicrosoftWindows 10 Version1607 HwPlatformx64
MicrosoftWindows 10 Version1607 HwPlatformx86
MicrosoftWindows 10 Version1809 HwPlatformarm64
MicrosoftWindows 10 Version1809 HwPlatformx64
MicrosoftWindows 10 Version1809 HwPlatformx86
MicrosoftWindows 10 Version1909 HwPlatformarm64
MicrosoftWindows 10 Version1909 HwPlatformx64
MicrosoftWindows 10 Version1909 HwPlatformx86
MicrosoftWindows 10 Version2004 HwPlatformarm64
MicrosoftWindows 10 Version2004 HwPlatformx64
MicrosoftWindows 10 Version2004 HwPlatformx86
MicrosoftWindows 11 Version- HwPlatformarm64
MicrosoftWindows 11 Version- HwPlatformx64
MicrosoftWindows 7 Version- Updatesp1 HwPlatformx64
MicrosoftWindows 7 Version- Updatesp1 HwPlatformx86
MicrosoftWindows 8.1 Version- HwPlatformx64
MicrosoftWindows 8.1 Version- HwPlatformx86
MicrosoftWindows Rt 8.1 Version-
MicrosoftWindows Server Version20h2
MicrosoftWindows Server Version2022
MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
MicrosoftWindows Server 2008 Versionr2 Updatesp2 HwPlatformx64
MicrosoftWindows Server 2008 Versionr2 Updatesp2 HwPlatformx86
MicrosoftWindows Server 2016 Version2004
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.41% 0.87
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
secure@microsoft.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.